Got Anything To Talk About? These Dutch Hackers Want You To Say It To Them

As we head into another Northern Hemisphere pandemic winter and hope that things won’t be quite as bad this year, next summer seems an extremely long time away in the future. But it will be upon us sooner than we might think, and along with it will we hope come a resumption of full-scale hacker Read more about Got Anything To Talk About? These Dutch Hackers Want You To Say It To Them[…]

Robinhood Hack Compromises Millions of Customer Email Addresses

Someone recently hacked and attempted to extort Robinhood, the popular investment and trading platform, gaining access to millions of customers’ email addresses and full names in the process. The platform revealed the security incident in a blog post published Monday, assuring users that nobody had lost any money as a result of the incident. “An Read more about Robinhood Hack Compromises Millions of Customer Email Addresses[…]

Hackers steal $130 million from Cream Finance; the company’s 3rd hack this year

Hackers have stolen an estimated $130 million worth of cryptocurrency assets from Cream Finance, a decentralized finance (DeFi) platform that allows users to loan and speculate on cryptocurrency price variations. The incident, detected earlier today by blockchain security firms PeckShield and SlowMist, was confirmed by the Cream Finance team earlier today. The attackers are believed to have found a vulnerability Read more about Hackers steal $130 million from Cream Finance; the company’s 3rd hack this year[…]

Hacker steals government ID database for Argentina’s entire population

A hacker has breached the Argentinian government’s IT network and stolen ID card details for the country’s entire population, data that is now being sold in private circles. The hack, which took place last month, targeted RENAPER, which stands for Registro Nacional de las Personas, translated as National Registry of Persons. The agency is a crucial cog Read more about Hacker steals government ID database for Argentina’s entire population[…]

Cybercrime Group Has Hacked Telecoms All Over the World since at least 2016

[…]A hacker gang, […] has been infiltrating telecoms throughout the world to steal phone records, text messages, and associated metadata directly from carrier users. That’s according to a new report from cybersecurity firm CrowdStrike, which published a technical analysis of the mysterious group’s hacking campaign on Tuesday. The report, which goes into a significant amount Read more about Cybercrime Group Has Hacked Telecoms All Over the World since at least 2016[…]

LANtenna attack reveals Ethernet cable traffic contents from a distance

An Israeli researcher has demonstrated that LAN cables’ radio frequency emissions can be read by using a $30 off-the-shelf setup, potentially opening the door to fully developed cable-sniffing attacks. Mordechai Guri of Israel’s Ben Gurion University of the Negev described the disarmingly simple technique to The Register, which consists of putting an ordinary radio antenna Read more about LANtenna attack reveals Ethernet cable traffic contents from a distance[…]

Woman Allegedly Hacked Flight School, Cleared Planes With Maintenance Issues to Fly

A woman allegedly hacked into the systems of a flight training school in Florida to delete and tamper with information related to the school’s airplanes. In some cases, planes that previously had maintenance issues had been “cleared” to fly, according to a police report. The hack, according to the school’s CEO, could have put pilots Read more about Woman Allegedly Hacked Flight School, Cleared Planes With Maintenance Issues to Fly[…]

Microsoft said it mitigated a 2.4 Tbps DDoS attack, the largest ever

Microsoft said its Azure cloud service mitigated a 2.4 terabytes per second (Tbps) distributed denial of service attack this year, at the end of August, representing the largest DDoS attack recorded to date. Amir Dahan, Senior Program Manager for Azure Networking, said the attack was carried out using a botnet of approximately 70,000 bots primarily Read more about Microsoft said it mitigated a 2.4 Tbps DDoS attack, the largest ever[…]

Neiman Marcus Breach Exposes Data Of 4.6 Million Users

Another day, another massive privacy breach nobody will do much about. This time it’s Neiman Marcus, which issued a statement indicating that the personal data of roughly 4.6 million U.S. consumers was exposed thanks to a previously undisclosed data breach that occurred last year. According to the company, the data exposed included login in information, Read more about Neiman Marcus Breach Exposes Data Of 4.6 Million Users[…]

The entirety of Twitch has reportedly been leaked – change your password!

An anonymous hacker claims to have leaked the entirety of Twitch, including its source code and user payout information. The user posted a 125GB torrent link to 4chan on Wednesday, stating that the leak was intended to “foster more disruption and competition in the online video streaming space” because “their community is a disgusting toxic Read more about The entirety of Twitch has reportedly been leaked – change your password![…]

Company That Routes Billions of Text Messages Quietly Says It Was Hacked – for years (you know, the messages we now use for 2FA)

A company that is a critical part of the global telecommunications infrastructure used by AT&T, T-Mobile, Verizon and several others around the world such as Vodafone and China Mobile, quietly disclosed that hackers were inside its systems for years, impacting more than 200 of its clients and potentially millions of cellphone users worldwide. The company, Read more about Company That Routes Billions of Text Messages Quietly Says It Was Hacked – for years (you know, the messages we now use for 2FA)[…]

Hackers Rob Thousands Coinbase Customers through SMS MFA Flaw – discloses today, happened around the IPO

Coinbase, a major U.S.-based bitcoin and cryptocurrency exchange, disclosed today that a hacker was able to bypass the company’s SMS multi-factor authentication mechanism and steal funds from 6,000 users, Bleeping Computer reported. The breach of Coinbase customers’ accounts happened between March and May 20, 2021, in a hacking campaign that combined phishing scams and a Read more about Hackers Rob Thousands Coinbase Customers through SMS MFA Flaw – discloses today, happened around the IPO[…]

New GriftHorse malware has infected more than 10 million Android phones

Security researchers have found a massive malware operation that has infected more than 10 million Android smartphones across more than 70 countries since at least November 2020 and is making millions of dollars for its operators on a monthly basis. Discovered by mobile security firm Zimperium, the new GriftHorse malware has been distributed via benign-looking apps uploaded Read more about New GriftHorse malware has infected more than 10 million Android phones[…]

110,000 Affected by Epik Breach – Including Those Who Trusted Epik to Hide Their Identity as hate mongerers

Epik’s massive data breach is already affecting lives. Today the Washington Post describes a real estate agent in Pompano Beach who urged buyers on Facebook to move to “the most beautiful State.” His name and personal details “were found on invoices suggesting he had once paid for websites with names such as racisminc.com, whitesencyclopedia.com, christiansagainstisrael.com Read more about 110,000 Affected by Epik Breach – Including Those Who Trusted Epik to Hide Their Identity as hate mongerers[…]

Hackers leak LinkedIn 700 million June data scrape

A collection containing data about more than 700 million users, believed to have been scraped from LinkedIn, was leaked online this week after hackers previously tried to sell it earlier this year in June. The collection, obtained by The Record from a source, is currently being shared in private Telegram channels in the form of a torrent file Read more about Hackers leak LinkedIn 700 million June data scrape[…]

FBI Had REvil’s Kaseya Ransomware Decryption Key for Weeks

The Kaseya ransomware attack, which occurred in July and affected as many as 1,500 companies worldwide, was a big, destructive mess—one of the largest and most unwieldy of its kind in recent memory. But new information shows the FBI could have lightened the blow victims suffered but chose not to. A new report from the Read more about FBI Had REvil’s Kaseya Ransomware Decryption Key for Weeks[…]

Alaska discloses ‘sophisticated’ nation-state cyberattack on health service

Alaska discloses ‘sophisticated’ nation-state cyberattack on health service A nation-state cyber-espionage group has gained access to the IT network of the Alaska Department of Health and Social Service (DHSS), the agency said last week. The attack, which is still being investigated, was discovered on May 2, earlier this year, by a security firm, which notified Read more about Alaska discloses ‘sophisticated’ nation-state cyberattack on health service[…]

Hackers leak passwords for 500,000 Fortinet VPN accounts

A threat actor has leaked a list of almost 500,000 Fortinet VPN login names and passwords that were allegedly scraped from exploitable devices last summer. While the threat actor states that the exploited Fortinet vulnerability has since been patched, they claim that many VPN credentials are still valid. […] The list of Fortinet credentials was Read more about Hackers leak passwords for 500,000 Fortinet VPN accounts[…]

FTC bans spyware maker SpyFone, and orders it to notify hacked victims

The Federal Trade Commission has unanimously voted to ban the spyware maker SpyFone and its chief executive Scott Zuckerman from the surveillance industry, the first order of its kind, after the agency accused the company of harvesting mobile data on thousands of people and leaving it on the open internet. The agency said SpyFone “secretly Read more about FTC bans spyware maker SpyFone, and orders it to notify hacked victims[…]

Gift Card Gang Extracts Cash From 100k Inboxes Daily

Some of the most successful and lucrative online scams employ a “low-and-slow” approach — avoiding detection or interference from researchers and law enforcement agencies by stealing small bits of cash from many people over an extended period. Here’s the story of a cybercrime group that compromises up to 100,000 email inboxes per day, and apparently Read more about Gift Card Gang Extracts Cash From 100k Inboxes Daily[…]

T-Mobile hacker explains how he breached carrier’s security

John Binns, a 21-year-old American who now lives in Turkey, told the Wall Street Journal that he was behind the T-Mobile security breach that affected more than 50 million people earlier this month. The intrigue: Binns said he broke through the T-Mobile defenses after discovering an unprotected router exposed on the internet, after scanning the Read more about T-Mobile hacker explains how he breached carrier’s security[…]

Mirai-style IoT botnet is now scanning for router-pwning critical vuln in Realtek kit

The remote code execution flaw, CVE-2021-35395, was seen in Mirai malware binaries by threat intel firm Radware, which “found that new malware binaries were published on both loaders leveraged in the campaign.” Warning that the vuln had been included in Dark.IoT’s botnet “less than a week” after it was publicly disclosed, Radware said: “This vulnerability Read more about Mirai-style IoT botnet is now scanning for router-pwning critical vuln in Realtek kit[…]

Belarus Hackers Seek to Overthrow Government, release huge trove of sensitive data

[…] The Belarusian Cyber Partisans, as the hackers call themselves, have in recent weeks released portions of a huge data trove they say includes some of the country’s most secret police and government databases. The information contains lists of alleged police informants, personal information about top government officials and spies, video footage gathered from police drones and detention centers Read more about Belarus Hackers Seek to Overthrow Government, release huge trove of sensitive data[…]

You Can Gain Admin Privileges to Any Windows Machine by Plugging in a Razer Mouse

[…] When you plug in one of these Razer peripherals, Windows will automatically download Razer Synapse, the software that controls certain settings for your mouse or keyboard. Said Razer software has SYSTEM privileges, since it launches from a Windows process with SYSTEM privileges. But that’s not where the vulnerability comes into play. Once you install Read more about You Can Gain Admin Privileges to Any Windows Machine by Plugging in a Razer Mouse[…]

Exclusive: Hacker Selling Private Data Allegedly from 70 Million AT&T Customers

A well-known threat actor with a long list of previous breaches is selling private data that was allegedly collected from 70 million AT&T customers. We analyzed the data and found it to include social security numbers, date of birth, and other private information. The hacker is asking $1 million for the entire database (direct sell) Read more about Exclusive: Hacker Selling Private Data Allegedly from 70 Million AT&T Customers[…]